Executive Summary
Europe’s cyber reporting rules crossed from proposal to obligation on 11 September 2026. Manufacturers selling products with digital elements in the EU market must now disclose actively exploited vulnerabilities and severe incidents. Authorities expect an early warning inside 24 hours of awareness and a full notification inside 72 hours. Filings run through the Single Reporting Platform that ENISA operates, which routes one submission to the coordinating CSIRT and onward to the member states where the product is sold.
The verdict is blunt. Reporting is now part of incident response, not a follow-up task. A company that handles the technical recovery well but misses the disclosure window still fails the obligation. Teams need a named owner, a pre-drafted early warning template, and a product inventory they can query under pressure. Open source stewards get until December 2027 before the same duties land. Everyone else shipping into Europe is already inside the deadline.
Europe started enforcing incident reporting deadlines on 11 September 2026. Manufacturers selling products with digital elements into the EU must now report actively exploited vulnerabilities and severe incidents. An early warning is due within 24 hours of becoming aware. A full notification follows within 72 hours.
That makes this the first hard legal deadline inside the Cyber Resilience Act, the EU rulebook that sets cybersecurity duties for hardware and software across their lifecycle. The obligation reaches anyone shipping software into Europe. Most incident response playbooks were never built for it. They assume the team finds a fix before anyone outside the company hears about the problem, and the law removes that assumption.

The clock starts when you become aware, not when you confirm
The window opens on awareness. A support ticket, a scanner hit, a customer email about exploitation in the wild. Any of these can start the clock, and the reporting obligations are strict about the trigger.
The early warning is deliberately thin. It states that an actively exploited vulnerability or a severe incident exists, and lists the member states where the product has been made available. The 72 hour notification carries the weight. It needs the nature of the exploit or incident, the product affected, an initial assessment, and the corrective or mitigating measures already taken or available to users.
A final report comes later. For actively exploited vulnerabilities it is due no later than 14 days after a corrective measure is available. For severe incidents, within a month.
None of these deadlines care about your internal severity scale. A bug that a customer reports as exploited is in scope the moment you know, even if your own triage calls it low. The clock is built around awareness, and awareness is not something a team can schedule.
One filing now reaches every regulator that matters
Manufacturers report once through the Single Reporting Platform that ENISA operates. The notification goes to the CSIRT in the country where the manufacturer has its main establishment. It is then shared with the other national CSIRTs on whose territory the product is available, and made available to ENISA at the same time.
Report once, reach everyone. Before this, a multinational vendor could be running separate disclosures through a dozen national processes, each with its own format and contact point. The SRP portal now routes one report outward to everyone who needs it, and ENISA says it will keep expanding functionality based on how teams actually use it.
Companies that cannot file directly do it through an Assigned Representative. ENISA has published registration and submission guidance for those users, which is a reminder that the platform expects a named account holder who presses submit. Delegating the account is fine. Delegating the accountability is not.
There is one narrow escape hatch. In December 2025 the Commission adopted a delegated act letting a CSIRT delay sharing a notification with other member states on justified cybersecurity grounds. Treat that as the exception, never the plan.
The operational consequence is blunt. Your escalation path has to survive a weekend, and someone has to own the disclosure while the outage is still being fought. A report drafted at hour 23 by an exhausted on-call engineer is a compliance risk.
Open source stewards get a longer runway, not a pass
Open source software stewards take on the same reporting duties from 11 December 2027. That is 15 months after manufacturers, and the delay sits in the Act itself. It is a delay, not an exemption. Stewards involved in the development of products with digital elements fall in scope.
The extra time is also a warning. Projects that end up inside commercial products will get pulled into supplier questionnaires and contracts long before the legal date arrives. Buyers will not wait until December 2027 to ask how a component handles vulnerability reporting, and a project that cannot answer will lose the deal.
Treat the reporting clock as production infrastructure. Wire alerting so a single security lead can draft a 24 hour warning without convening a war room. Rehearse the 72 hour notification the way you rehearse a failover. The teams that handle this cleanly will be the ones that already know what they ship and where it runs. If that inventory lives in three spreadsheets and one engineer’s memory, the deadline will find you first.
Where this sits in the wider market
Reporting duties are one part of a wider shift in software supply chain accountability. The 2026 State of Enterprise Infrastructure report covers the security half of that picture, including why most organisations have already absorbed a supply chain incident and which tooling actually holds up.
Related reading. Digital Sovereignty Is a Procurement Problem, Not a Data Center Problem. Attackers Chained Three JFrog Artifactory Flaws Into Full Admin Control. Sovereign Cloud Is Not Data Residency, and the Gap Costs Money. AI Infrastructure Runs on Four Layers. Most Break Below the Model..
Get the next one before it is old news
Independent analysis of cloud-native infrastructure, Kubernetes and data centre economics. No vendor spin.
